The philosophy behind XAMPP is to build an easy to install distribution for developers to get into the world of Apache. To make it convenient for developers XAMPP is configured with all features turned on.

The default configuration is not good from a securtiy point of view and it's not secure enough for a production environment - please don't use XAMPP in such environment.

As mentioned at another place, XAMPP is not meant for production use but only for developers in a development environment. XAMPP is configured is to be as open as possible and to allow the web developer anything he/she wants. For development environments this is great but in a production environment it could be fatal.

Okay here is MY problem. I have been using xampp for win 32 since 1.3 something for 5+yrs and never had 1 single break in security. So for the record, that task I undertook then, took 2 yrs of hard research and every spare moment of my time and learning Apache PHP FTP and oh my god mercury mail and Pegasus and well then to get the tomcat server and all working in harmony with MY program for four (4) years. So you want horror stories I can tell a few with the best of them. I understand noob stuff okay I get it but some of us didn't need to be protected from ourselves! I Could understand if I was a for profit and/or was making money off of the programs but i just run a FREE game server with stats and the game is still popular get hits all the time till this Okay have I ranted enough for the 4 years of bragging about you and your awesome Group and their Programs? if so please tell me the secret to undo this at "my own risk", which I agreed to when I downloaded it all those years ago E:/xampp/apache/conf/extra/httpd-xampp.conf: I know the problems only start here here server running win 2003 std ed present xampp 1.7.3 12 gig ram with twin xeons days over so ill check 1-15-13 gmt +7 or MST around 10 am local time please help On a more personal note I live close to Apache Jct Arizona USA and i shudder at the though of not using Apache